- Experience
- 10+ yrs
- Salary
- USD 203,200 – USD 275,000 / year
- Openings
- 1
- Posted
- 4 days ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About GitLab and Role Overview
GitLab is a leading intelligent orchestration platform designed for DevSecOps, trusted by more than 50 million users including over half of the Fortune 100 companies. GitLab’s mission is to boost developer productivity, improve operational efficiency, minimize security and compliance risks, and accelerate digital innovation. The company fosters a culture where AI is used as a key productivity enhancer embedded into daily workflows, and employees collaborate extensively to innovate and tackle complex challenges.
Role Purpose
We are seeking a Principal Security Researcher to join our Application Security Team, focusing on cutting-edge security research related to GitLab’s AI-integrated DevSecOps products. This role involves proactively discovering and validating vulnerabilities prior to impacting the platform or clients. The successful candidate will work with GitLab’s DevSecOps platform, Duo Agent Platform, GitLab Duo Chat, and AI-driven workflows that signify the future integration of human and AI collaboration in development.
Responsibilities
- Lead security research projects across diverse domains.
- Detect novel and complex vulnerabilities, especially those combining multiple weaknesses for significant impact.
- Validate findings through hands-on penetration testing and develop proof-of-concept exploits demonstrating realistic attack scenarios.
- Analyze new vulnerability types emerging in the industry and drive fixes that address entire vulnerability classes rather than just specific instances.
- Direct security research focused on GitLab’s AI and autonomous agent surfaces, defining security requirements for engineering teams.
- Create and manage tools and automation to scale vulnerability discovery, including AI-assisted methods.
- Evaluate the security posture of open-source tools and dependencies integrated with GitLab, communicate findings to maintainers, and oversee mitigation aligned with responsible disclosure practices.
- Solve highly complex and ambiguous technical challenges.
- Contribute to the strategic roadmap of the security team and sub-departments.
- Facilitate the incorporation of research discoveries into engineering and business processes.
- Mentor and guide experts and contributors across various teams.
- Disseminate novel vulnerability insights to the wider security community.
Qualifications
- More than 10 years of relevant experience in security research, penetration testing, or offensive security roles.
- Proficient in uncovering and exploiting security weaknesses in large-scale and complex codebases.
- Experience with at least two programming languages among Ruby, Go, Python, TypeScript, or Rust.
- Ability to comprehend and analyze code written in multiple languages across diverse codebases.
- Strong background in AI frameworks and a deep understanding of AI-related attack vectors such as prompt injection, agent manipulation, and workflow exploitation.
- Skilled at organizing and driving complex remediation initiatives involving multiple teams.
- Exceptional written communication capabilities, able to articulate intricate topics with clarity and precision.
- Competent at translating complex technical vulnerabilities into clear risk evaluations and actionable remediation advice.
- Analytical mindset with innovative problem-solving focused on sophisticated attack techniques.
- Preferred but not required: Published security research or talks; background in software engineering of distributed systems; prior experience with GitLab or similar DevSecOps platforms.
Team and Culture
The Application Security team focuses on systemic risks within the product and collaborates across departments to maintain security while supporting engineering agility. This role offers a chance to influence security in one of the world’s foremost DevSecOps platforms.
Compensation and Benefits
The salary range for this level in the United States is $203,200 to $275,000 USD, excluding bonuses, equity, or benefits. GitLab offers a comprehensive benefits package including health support, flexible time off, employee resource groups, equity plans, development funds, and parental leave.
Diversity and Inclusion
GitLab values diversity and inclusion, encouraging candidates from various backgrounds to apply, including those who may not meet every qualification. The company is committed to equal opportunity employment and accommodates individuals with disabilities throughout the recruitment process.